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(see Rule 70.16 and Section 607 of the Administrative instructions under the PCT). 

These annexes consist of a total of sheets. 
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EXAMINATION REPORT International application No. PCT/CA 03^00307 



I. Basis of the report 

1 . Witli regard to tlie elements of the international application (Replacement sheets which have been furnished to 
the receiving Office in response to an invitation under Article 14 are referred to in this report as ''originally filed" 
and are not annexed to this report since they do not contain amendments (Rules 70. 16 and 70. 17)): 



Description, Pages 

1-13 as originally filed 

Claims, Numbers 

1-18 as originally filed 

Drawings, Sheets 

1 M-4y4 as originally filed 

2. With regard to the language, ail the elements marked above were available or furnished to this Authority in the 
language in which the intemational application was filed, unless othenAfise indicated under this item. 

These elements were available or furnished to this Authority in the following language: , which is: 

□ the language of a translation furnished for the purposes of the international search (under Rule 23.1 (b)). 

□ the language of publication of the international application (under Rule 48.3(b)). 

□ the language of a translation furnished for the purposes of intemational preliminary examination (under 
Rule 55.2 and/br 55.3). 

3. With regard to any nucleotide and/Dr amino acid sequence disclosed in the international application, the 
intemational preliminary examination was carried out on the basis of the sequence listing: 

□ contained in the international application in written fomn. 

□ filed together with the intemational application in computer readable form. 

□ furnished subsequently to this Authority in written form. 

□ furnished subsequently to this Authority in computer readable form. 

□ The statement that the subsequently furnished written sequence listing does not go beyond the disclosure 
in the international application as filed has been furnished. 

□ The statement that the information recorded in computer readable form is identical to the written sequence 
listing has been fumished. 

4. The amendments have resulted in the cancellation of: 

□ the description, pages: 

□ the claims, Nos.: 

□ the drawings, sheets: 
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5. □ This report lias been established as if (some of) the amendments had not been made, since they have 

been considered to go beyond the disclosure as filed (Rule 70.2(c)). 

(Any replacement sheet containing such amendments must be refenred to under item 1 and annexed to this 
report.) 

6. Additional observations, if necessary: 

V. Reasoned statement under Article 35(2) with regard to novelty, inventive step or industrial appiicability; 
citations and explanations supporting such statement 

1. Statement 

Novelty (N) Yes: Claims 1-18 

No: Claims 

Inventive step (IS) Yes: Claims 

No: Claims 1-18 

Industrial applicability (lA) Yes: Claims 1-18 

No: Claims 

2. Citations and explanations 
see separate sheet 
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Re Item V 

Reasoned statement under Article 35(2) with regard to novelty, inventive step or 
industrial applicability; citations and explanations supporting such statement 

1 The following document is cited by the Examiner: 

D1 : WO 9827502 A1 (INTEL CORPORATION) 25 June 1998 (1 998-06-25) 

2 The present Invention relates to a system (claim 1) , a method (claim 5) . a computer 
program (claim 13), and an apparatus (claim 18) for identifying and notifying 
unauthorised access to data network services. 

3 The following unclarlties (Article 6 PCT) affect the assessment of novelty and 
inventive step of the underlying subject-matter: 

3.1 The independent claims 1 , 5, 1 3, and 18, related to the same embodiment, are 
not consistent since they do not comprise the same essential features (e.g., 
"initiation of a notification process") according to said embodiment, thereby 
rendering the scope of protection sought unclear. 

3.2 The wording of claim 1 8, namely "In a computer...said computer comprising...", 
leaves doubt as to whether protection is sought for a "computer" per se or for 
the individual components of the computer. Hence, the scope of this claim is 
unclear (see PCT-Gazette, IV, lll-4.8a). 

4 The present application does not meet the criteria mentioned in Article 33(1) PCT, 
because the subject-matter of independent claims 1, 5, 13, and 18 does not involve 
an inventive step in the sense of Article 33(3) PCT. 

4.1 Document D1 , which is considered to represent the closest prior art, discloses 
in accordance with features of claim 5 (the references in parentheses applying 
to this document): 

a method for identifying unauthorised access to a data network service, 
provided at a service node ("host system" in Fig. 1 , ref. 120) in a data network 
(see Fig. 1), by a user node ("client system" in Fig. 1, ref. 110) in said data 
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network, of steps comprising: 

(a) retrieving a user access list ("log data"; see Figs. 3, 4, refs. 325, 430), for 
a given period of time in said data network (page 12, lines 4-1 0 and 17-20; 
page 14, lines 3-15; see Fig. 6, ref. 605 and Fig. 7, ref. 715); 

(b) comparing said user access list to an authorised user access list (page 1 5, 
lines 15-18); 

(c) determining an unauthorised access based on said comparison (page 15, 
lines 18-20); 

(d) if unauthorised access determined, initiating a notification process (page 
15, lines 18-25). 

4.2 The subject-matter of claim 5 of the present application differs from that in 
document D1 in that the user access list is retrieved from an agent aLsaid 
sarvicQ node. 

4.3 The objective problem to be solved by claim 5 may therefore be regarded as 
how to reduce complexity and costs in a user access supervision system. 

4.4 Starting from the technical teaching of document D1 , in which the retrieval of a 
user access list ("log data") from a "log sender" (Figs. 1 and 5, ref. 150) not 
being part of a service node ("host system") is disclosed (e.g., Fig. 7, ref. 715), 
the skilled person would readily incorporate the functionality of the log sen/er, 
namely maintenance and provision of log data such as user access and 
authorised user access lists, into a single unit, i.e. the sen/ice node ("host 
system") in order to combine the features of a typical service node and a log 
node, thereby eliminating the shortcoming of the approach described in D1 
based on common knowledge. 

Moreover, this integration of functions would not produce any non-obvious 
inten^latidnships and technical effects, rather both units are supposed to 
function in their nonmal way. As a result, the skilled person would arrive at the 
subject-matter of claim 5 in an obvious manner In order to solve the objective 
problem stated above. 

4.5 As a consequence, claim 5 does not comply with the provisions set out in 
Article 33(3) PCT due to lack of inventive step of its subject-matter. 
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4.6 Referring to the objection raised above, claims 1,13, and 18, insofar as they 
can be understood properly (see item 3 above), do also not comply with the 
requirements of Article 33(3) PCT due to lack of inventive step since their 
subject-matter corresponds to that of claim 5 . whereby all the method steps of 
claim 5 are represented by corresponding structural features (claims 1 and 18) 
or by a computer program (claim 13). 

4.7 Accoreling to the Applicant, D1 does not disclose the retrieval of a user access 
list but rather the interception of the access request prior to the access 
performed. However, D1 clearly and unambiguously discloses the retrieval of 
a user access list ("log data") since it is stated therein that "the log server first 
iBceives a request for the log data from a supervisor" and further that "the log 
data retrieval process provides a summary of the log data to the supervisor" 
(page 14, lines 4-5 and 14-15; see Fig. 7, refs. 705, 715). 

4.8 Furthermore, it is agreed that the authorised access list Is stored locally on the 
client machine according to D1 . However, D1 also explicitly discloses that the 
"permanent access database" (see Fig. 5, ref. 530) residing In the "access 
database control process" (see Fig. 5, ref. 527) of the "log server" stores access 
lists (page 12, last paragraph) as well. 

5 Additionally, dependent claims 2-4, 6-12, and 14-17 do not appear to contain any 
additional technical features which, either alone or in combination with the features 
of any claim to which they refer, meet the requirements of the PCT with respect to 
inventive step (Article 33(3) PCT) since their subject-matters are either known from 
the prior art (document D1; page 13, lines 4-6; page 15, lines 5-11) regarding claim? 
6. 10. 11. 14. 16 or merely represent minor design options to the person skilled in the 
art regarding claims 2-4. 7-9. 12. 15. 17. 

6 In the light of the above-mentioned reasons, the present application does not comply 
with the criteria mentioned in Article 33(1) PCT due to lack of Inventive step (Article 
33(3) PCT) of its subject-matter. 

7 Finally, the following additional remari<s are given: 

7.1 The Independent claims are not properly drafted in the two-part form 
recommended by Rule 6.3(b) PCT and do not include reference signs in 



Form PCT/Separate Sheet/409 (Sheets) (EPO-April 1997) 



t 

« « • * 



INTERNATIONAL PRELIMINARY International application No. PCT/CA03/00307 
EXAMINATION REPORT - SEPARATE SHEET 

parentheses to increase their intelligibility according to Rule 6.2(b) PCT. 

7.2 The prior art documents are not properly acknowledged in the description part 
according to Rule 5.1(a)(ii) PCT. 
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